Ukrainian Government Targeted by Sophisticated Cyberattack Linked to Moscow
A Ukrainian government organisation has been targeted by a sophisticated cyberattack linked to Moscow. In April, Cisco's cybersecurity researchers noticed unusual activity in the organisation's computer systems and assessed with moderate confidence that a Russian threat actor carried out the attack.
The Amatera malware was found running on the system, capable of stealing sensitive information and installing software that could give an attacker access to the computer. The software was configured to connect to a server with an IP address based in Russia.
Cisco researchers discovered that the Ukrainian infection might have started through compromised websites showing fake versions of Google's CAPTCHA verification check. Instead of asking users to tick a box or identify images, the fake check told them to open a window on their computer and paste in text that would run malware.